Senior IT Engineer
IT
Nigeria
About Paystack
Paystack’s mission is to power African ambition. Over 300K businesses across Nigeria, South Africa, Ghana, and Kenya use Paystack’s modern payments gateway, including Qatar Airways, MTN, Burger King, UPS, Africa World Airlines, AXA Mansard Insurance, FairMoney, PiggyVest, Crocs, Under Armour, Richemont Lifestyle Group, and many others.
Over the last 10 years, we’ve built products that have helped shape online payments in Africa, from automated recurring payments to direct bank payments and automated chargebacks. Today, Paystack is part of The Stack Group (TSG), a family of technology brands building modern infrastructure across payments, banking, consumer products, and emerging technologies.
At Paystack, we hire talented people, treat them with genuine respect, and give them the space, resources, and support to do the best work of their lives. We’d love your help.
About the Senior IT Engineer role
Our IT Operations team is a small, high-impact platform engineering unit. We manage the identity, endpoint, network, and access infrastructure for over 300 employees and 100+ outsourced agents across six offices (Lagos, Nairobi, Accra, Cape Town, and Dubai).
We manage a fully automated macOS fleet, every physical office network, and roughly thirty core applications secured behind SSO. We do all of this inside a highly regulated fintech environment that holds PCI-DSS and ISO 27001 certifications and operates under the CBN.
Our environment is heavily integrated and highly automated. We’ve built an identity lifecycle that flows automatically from our HR systems into our identity provider. Macs deploy zero-touch, and access requests provision themselves.
As our scale and complexity increase, we are bringing on a Senior IT Infrastructure Engineer to expand our engineering capacity and provide critical redundancy across our Tier-1 systems. Reporting directly to the Head of IT, you will help drive, manage, and maintain this integrated ecosystem while executing on our long-term infrastructure roadmap.
We’ll trust you to
Drive Identity Management: Manage our identity lifecycle. You will configure SAML and OIDC across our application estate, maintain SCIM provisioning, manage attribute-driven RBAC, and enforce phishing-resistant authentication.
Maintain Lifecycle Automation: Support and improve the joiner/mover/leaver pipeline. Build automated processes for accessmenent from approval to access provisioning
Manage the Fleet & Device Trust: Oversee our macOS environment. This includes automated enrollment, configuration profiles, EDR, and enforcing DLP on outsourced devices. You will help maintain device trust as a real, certificate-backed control that rejects unmanaged or unpatched devices.
Maintain Global Networks: Manage the physical network across six locations. You’ll handle multi-WAN failover, VLAN segmentation, centrally managed wireless/switching, server rooms, and the carrier connectivity linking our on-premise infrastructure to the cloud.
Drive the Zero Trust Migration: Help us execute the transition away from legacy VPNs. You will drive our move to Zero Trust Network Access (ZTNA), enforcing per-application authorization based on real-time device posture.
Build as Code: Treat the IT environment as code. You’ll use Terraform, Git-based staging-to-production pipelines, and Python/Bash where no provider exists. Your first instinct should always be to reach for an API before logging into an admin console.
Enforce Automated Compliance: Turn regulatory requirements into automated controls that generate their own evidence. We balance ISO 27001, ISO 20000, PCI-DSS, NDPR, and the CBN IT Blueprint simultaneously.
Resolve Complex Tickets: We all work tickets leadership included. You will handle complex escalations and diagnose faults that span a firewall, a carrier, and a cloud provider all at once.
Document for the Future: Write documentation to a standard that survives your absence.
You’ll thrive in this role if you have
5+ years in infrastructure or systems engineering, ideally including time on a small, high-leverage team.
Real depth in at least two of the four areas below, and enough baseline competence in the rest to handle an escalation (we are not looking for a unicorn who is a master of all four):
Identity & Access Management: SAML 2.0, OIDC, OAuth 2.0, SCIM 2.0, LDAP, WebAuthn/FIDO2. You have actually built lifecycle automation, not just clicked through SSO setup wizards.
Endpoint Management at Scale: Apple MDM protocols, zero-touch enrollment, declarative configurations, and compliance enforcement across hundreds of devices.
Network Engineering: Multi-site and multi-carrier setups, VLANs, complex routing, firewall policies, multi-WAN failover, 802.1X, and RADIUS.
Infrastructure as Code: Terraform, Git workflows (with peer review), and enough Python, Go, or Bash to confidently build against a REST API.
You should also have:
Experience operating under external assessors with multiple active compliance frameworks.
A track record of inheriting live, critical systems and improving them without breaking what already works.
The engineering judgment to know when not to automate. (Not everything needs to be code).
Strong technical writing skills. You write specs, procedures, and audit responses that other teams can actually understand and act on.
Bonus points if you
Experience with public cloud networking, certificate management, and identity federation.
Knowledge of X.509, mTLS, ACME, or SCEP for certificate-backed device identity.
Experience using osquery (or equivalent) and turning CIS benchmarks into enforced configurations.
Experience enforcing security baselines on BPOs and devices you do not physically own.
Tenant-level administration of enterprise collaboration suites, including deep DLP classification.
ITSM design experience under ISO 20000 or ITIL.
Benefits
Competitive compensation package and benefits
13th month bonus
TSG Equity compensation
Full medical coverage
Wellbeing stipend
Hybrid working environment
Smart, kind colleagues who are invested in your growth.
Paystack is an equal opportunity employer and prohibits discrimination and harassment of any kind. We’re committed to providing employees with a work environment that is progressive and open-minded. Our employment philosophy is to hire the best people and empower them to do the best work of their lives. Employment decisions are based on business needs and individual merit without regard to race, color, religion, ethnicity, sexual orientation, nationality, marital status, gender, or age.